T09 · Insecure Skill Coding Practices
- Location
references/api-templates.md:44- Finding
Partner API Key Sent to an Unrestricted Runtime-Configured Destination
- Content
View full analysis
Vulnerability Details
File Location:
references/api-templates.md, lines 44-50
Vulnerability Type: Unrestricted credential destination
Risk Level: HighComplete Code Snippet:
ts async function brekRequest(path: string, init?: RequestInit) { const response = await fetch(`${BREK_BASE_URL}${path}`, { ...init, headers: { 'content-type': 'application/json', 'x-partner-api-key': BREK_PARTNER_API_KEY, ...(init?.headers || {}) } });Technical Analysis
The transport wrapper automatically sends
BREK_PARTNER_API_KEYto the origin specified byBREK_BASE_URL. Although transmitting a credential is necessary to authenticate to the Brek API, the Skill does not require validation of the URL's scheme, hostname, port, embedded credentials, or resolved network address.Because
BREK_BASE_URLis a required runtime value rather than a fixed or allowlisted Brek endpoint, anyone capable of influencing deployment configuration can redirect authenticated requests to an attacker-controlled destination. This exceeds the minimum network privilege needed for the declared integration.The wrapper also does not define a redirect policy. Depending on the runtime's
fetchbehavior, redirects may create additional unintended network exposure. Furthermore, spreadinginit.headersafter the default headers permits callers to override authentication and content-type headers. That is not the primary credential-disclosure path, but it weakens the wrapper's security invariants.Attack Path
- An attacker gains influence over the environment or runtime configuration supplying
BREK_BASE_URL. - The attacker changes it to an HTTP or HTTPS server under their control.
- A user invokes a normal hotel-search, booking, or payment-confirmation flow.
brekRequestconstructs the destination from the attacker-controlled base URL.- The wrapper sends
BREK_PARTNER_API_KEYan ...[truncated 884 chars]
- An attacker gains influence over the environment or runtime configuration supplying
- Remediation
View remediation
Remediation Suggestions
- Use a fixed official Brek API origin in production instead of accepting an arbitrary runtime base URL.
- If configurability is required, parse the value with a standard URL parser and enforce:
- The
https:scheme. - An exact allowlist of approved Brek hostnames.
- The expected port.
- No username or password in the URL.
- No fragments or unexpected base paths.
- Rejection of localhost, IP literals, private networks, link-local addresses, and cloud metadata addresses.
- The
- Resolve endpoint paths with
new URL(path, approvedBaseUrl)and verify that the resulting origin remains identical to the approved origin. - Disable redirects or validate every redirect target before following it.
- Prevent
init.headersfrom overriding security-critical headers. Merge caller headers first, then set the validated authentication header explicitly. - Scope the API key to the minimum required tenant and API operations, rotate it periodically, and immediately rotate it after suspected exposure.
- Ensure authorization headers, API-key headers, and request bodies containing sensitive identifiers are redacted from logs.
- Add automated tests proving that unapproved schemes, hosts, ports, redirects, and private network destinations are rejected before credentials are attached.
